← Back

CVE-2003-0174

nvd nist
Published: May 12, 2003Modified: Apr 16, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.

Affected (1)

Products: Sgi: Irix
1 product
Irix
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 6.5.19

References (8)

ftp://patches.sgi.com/support/free/security/advisories/20030407-01-P (unsafe URL)
Source: cve@mitre.org
Broken LinkPatchVendor Advisory
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Broken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
ftp://patches.sgi.com/support/free/security/advisories/20030407-01-P (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.